Restrict Device Join to Specific Group in Microsoft Entra ID
You have a Microsoft 365 E5 subscription that contains a group named Group1. You need to ensure that only the members of Group1 can join devices to the Microsoft Entra tenant. What should you configure in the Microsoft Entra admin center?
Community Insight
The question tests the ability to manage who can join devices to an Entra tenant, with the common trap being confusion between global user settings and specific device configuration policies.
This page explains how to configure Microsoft Entra ID device settings to restrict device joining permissions to a specific security group. It clarifies the correct navigation path within the Entra admin center to enforce this identity compliance policy.
Learners often select 'User settings' because it involves users, but this area manages personalization and roaming rather than device registration permissions.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
To restrict which users or groups can join devices to the Microsoft Entra tenant, you must navigate to Identity > Devices > Device settings in the Microsoft Entra admin center. Within this section, there is a specific setting labeled "Users may join devices to Azure AD" (or Microsoft Entra ID). By changing this setting from "All" to "Selected," you can specify exactly which groups, such as Group1, are permitted to perform the device join action.Why the Other Options Are Wrong
Option B, Mobility, relates to Mobile Device Management (MDM) and Mobile Application Management (MAM) policies for iOS/Android, not Windows device join restrictions. Option C, Enterprise State Roaming, controls the synchronization of browser favorites and IE settings across devices, which is unrelated to device identity registration. Option D, User settings, generally refers to user-specific configurations like background images or desktop apps, not the global tenant-level permission for device joining.Community Comment Notes
Community members confirm that the Device settings blade is the correct location. As one commenter noted, the setting "Users may join devices to Azure AD" allows you to select specific groups, ensuring only Group1 members can join devices. Another user verified that navigating through Manage > Devices leads directly to the required configuration.Exam Strategy
When configuring tenant-wide permissions for device identity, always look for the 'Device settings' node under the Devices category. Remember that 'User settings' manage personal preferences, while 'Device settings' manage the technical relationship between the device and the directory.
Frequently Asked Questions
Where is the 'Users may join devices' setting located?
It is found in the Microsoft Entra admin center under Identity > Devices > Device settings.
Can I use User settings to control device joins?
No, User settings manage personalization and roaming; Device settings control join permissions.
Related Analysis
Practice All MD-102 Questions
Access 92 questions with complete answers and detailed explanations.
View Full MD-102 Practice Test →